VulnerabilityModified
CVE-2013-4356
Xen 4.3.x writes hypervisor mappings to certain shadow pagetables when live migration is performed on hosts with more than 5TB of RAM, which allows local 64-bit PV guests to read or write to invalid memory and cause a denial of service (crash).
MEDIUM 5.4EPSS 0.61%
Does this matter?
Lower severity and a low EPSS score (0.61%). Track it; it rarely justifies an emergency change on its own.
Description
Xen 4.3.x writes hypervisor mappings to certain shadow pagetables when live migration is performed on hosts with more than 5TB of RAM, which allows local 64-bit PV guests to read or write to invalid memory and cause a denial of service (crash).
- CVSS 2.0
- 5.4 MEDIUMAV:A/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 0.61% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- xen/xen
- Source
- secalert@redhat.com
References
- http://secunia.com/advisories/54962Vendor Advisory
- http://security.gentoo.org/glsa/glsa-201407-03.xml
- http://www.openwall.com/lists/oss-security/2013/09/30/2
- http://www.securityfocus.com/bid/62709
- http://secunia.com/advisories/54962Vendor Advisory
- http://security.gentoo.org/glsa/glsa-201407-03.xml
- http://www.openwall.com/lists/oss-security/2013/09/30/2
- http://www.securityfocus.com/bid/62709
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.